Cisco Patches Nine Secure Firewall ASA/FTD Vulnerabilities, Including ACL Bypass and Eight Denial-of-Service Flaws
On September 16, 2026, Cisco released software updates for nine vulnerabilities in Secure Firewall ASA and FTD software: one ACL Object Group Search access control bypass and eight denial-of-service flaws, all exploitable by unauthenticated attackers; the…
Cisco disclosed and patched a batch of vulnerabilities in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software on September 16, 2026. The most notable is an ACL Object Group Search bypass caused by a logic error in populating group access control policies, which lets an unauthenticated remote attacker send traffic that should be blocked through the device. The other eight advisories describe denial-of-service conditions: improper DTLS resource management on Secure Firewall 3100 and 4200 series devices; a DNS-over-TCP buffer-size tracking error; a TLS 1.3 buffer management flaw in FTD that crashes the LINA process; incomplete SSL certificate validation in FTD's Snort 2 Detection Engine; an IKEv2 certificate authentication logic error; improper rate limiting of syslog message 419002 that drives high CPU under TCP SYN floods; an EIGRP memory-leak flaw exploitable by an adjacent attacker; and system memory or buffer block exhaustion in the VPN and management web servers. All flaws are exploitable by unauthenticated attackers — remote in every case except EIGRP, which requires adjacent access. Cisco has released software updates for all nine; the Snort 2 advisory explicitly states no workarounds are available, and no workarounds or active exploitation are mentioned for the others.
- Nine Cisco advisories dated September 16, 2026 cover Secure Firewall ASA and FTD software: one access control bypass and eight denial-of-service flaws
- ACL Object Group Search bypass: a logic error in populating group access control policies lets an unauthenticated remote attacker pass traffic that should be blocked; affects both ASA and FTD
- DTLS denial of service affects ASA and FTD only on Secure Firewall 3100 and 4200 series; a crafted stream of DTLS traffic forces the device to reload
- DNS-over-TCP flaw: a logic error mishandling buffer-size tracking lets a crafted DNS reply to a device-originated query restart the TCP DNS response handler and reload the device
- TLS 1.3 flaw (FTD only): crafted TLS 1.3 packets to a TLS 1.3-enabled listening socket crash the LINA process, with the reload possible before or after connection authentication
- Snort 2 flaw (FTD only): incomplete SSL certificate validation lets a crafted SSL connection setup request restart the Snort 2 Detection Engine; no workarounds available
- IKEv2 flaw: a crafted certificate offered during VPN connection setup crashes the IKEv2 process and causes an unexpected device reload
- Logging flaw: improper rate limiting of syslog message 419002 lets a flood of TCP SYN packets cause high CPU utilization and performance degradation rather than a reload
Coverage timelineoldest first · each row is one article
- · 2h agoCisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability
Cisco Security Advisories· 32
Cisco fixed an SSL certificate parsing flaw in FTD's Snort 2 engine letting unauthenticated remote attackers force detection engine restarts.
- · 2h agoCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability
Cisco Security Advisories· 35
Cisco disclosed a TCP DNS flaw in ASA and FTD firewall software letting unauthenticated remote attackers trigger device reloads and denial of service.
- · 2h agoCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability
Cisco Security Advisories· 28
Cisco fixed an EIGRP flaw in Secure Firewall ASA/FTD software letting unauthenticated adjacent attackers trigger memory leaks and unexpected device reloads.
- · 2h agoCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities
Cisco Security Advisories· 48
Cisco patched ACL Object Group Search bypass flaws in ASA and FTD firewall software that let unauthenticated attackers reach protected networks.
- · 2h agoCisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability
Cisco Security Advisories· 35
A TLS 1.3 buffer management flaw in Cisco Secure Firewall Threat Defense lets remote attackers crash the LINA process and reload devices.
- · 2h agoCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability
Cisco Security Advisories· 28
Cisco patched an ASA/FTD rate-limiting flaw where TCP SYN floods trigger excessive syslog 419002 messages, causing high CPU and degraded performance.
- · 2h agoCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability
Cisco Security Advisories· 40
Cisco patched a DTLS flaw in ASA and FTD software for Secure Firewall 3100/4200 series letting unauthenticated attackers trigger device reloads.
- · 2h agoCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability
Cisco Security Advisories· 32
Cisco patched an ASA/FTD IKEv2 certificate authentication flaw letting unauthenticated remote attackers crash the IKEv2 process and reload devices with crafted certificates.
- · 2h agoCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability
Cisco Security Advisories· 45
Cisco expanded an SSL VPN denial-of-service advisory to cover all ASA and FTD software platforms; unauthenticated attackers can exhaust device memory.